🔴 Critical  |  Source: Microsoft Security Response Center


A remote code execution vulnerability (CVE-2026-50517) has been identified in Microsoft 365 Copilot, caused by insecure handling of untrusted data during deserialization. An attacker who already has authorised access to the service could exploit this flaw to run arbitrary code across the network. Given M365 Copilot’s deep integration with enterprise data and Microsoft 365 services, successful exploitation could have significant downstream impact.

Security Architect’s Take: Review your organisation’s M365 Copilot deployment and apply any available Microsoft patches or mitigations immediately. In the interim, assess whether network-level controls or conditional access policies can limit exposure, and audit which accounts hold authorised access to Copilot to reduce the potential attacker surface.

Original advisory: CVE-2026-50517 Microsoft M365 Copilot Remote Code Execution Vulnerability